RHSA-2026:26994HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
June 18, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-45491 — dotnet: .NET: Local file tampering via link following vulnerability CVE-2026-45591 — dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-59724 — engine.io: Engine.IO: Denial of Service via crafted WebTransport session ID CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document

🔗 References (10)